Senior Security Strategist Lead
Redmond, Washington, Us
I ran the Security Community Outreach and Strategy team for Microsoft as part of the Microsoft Security Response Center (MSRC) team to help drive crucial elements of our security community strategy effort. • I created the first Microsoft security bounty programs (www.microsoft.com/bountyprograms). We paid over $253,000 and received 18 vulnerabilities and new attack techniques to help us build stronger defenses that will protect the entire platform from this new class of attack. • Serve as lead subject matter expert in the US National Body for the ISO work item 29147 "Vulnerability Disclosure", published in 2014. • I am the editor of a new International Standard ISO 30111 Vulnerability handling processes, published in 2014, which outlines the steps vendors need to take in order to investigate, triage, and remediate vulnerabilities in products of online services.• Owner of vulnerability disclosure policy for Microsoft in terms of overall strategy, evolution, policy creation, messaging, and I serve as the external spokesperson for all disclosure-related matters for Microsoft. • Drove an industry-wide shift in disclosure terminology and practice, winning the support of dozens of researchers, vendors, CERTs and other industry notables in the process. http://blogs.technet.com/b/ecostrat/archive/2010/07/22/coordinated-vulnerability-disclosure-bringing-balance-to-the-force.aspx• Drove a new reward for defensive security research incentives with the BlueHat Prize (www.bluehatprize.com), which paid over $260,000 to security researchers to design novel defensive mitigation technology.• Seasoned security spokesperson with nearly a decade of corporate spokesperson experience. I have appeared on the Engadget show, in numerous print media, as well as done audio and video podcasting. Media outlets I have been quoted in include BBC, Reuters, ComputerWorld, ComputerWeekly, ThreatPost, Ars Technica, Dark Reading, ZDNet, eWeek, Engadget, and others.